Page MenuHomeVyOS Platform
Feed Search

Aug 17 2023

Apachez added a comment to T5478: Cannot configure resolver-cache options for firewall.

This error not only occurs for new settings in global-options but also for older:

Aug 17 2023, 7:08 PM · VyOS 1.4 Sagitta
Apachez updated the task description for T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Aug 17 2023, 5:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez created T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Aug 17 2023, 5:50 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Aug 16 2023

Apachez added a comment to T5160: Firewall refactor.

If there would never be such then "INVALID" wouldnt exist as an option.

Aug 16 2023, 7:05 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

2.2: Invalid shall ALWAYS be processed BEFORE established/related/other rules otherwise it will not serve it purpose.

Aug 16 2023, 5:06 AM · VyOS 1.4 Sagitta

Aug 14 2023

Apachez closed T5457: Add environmental variable pointing to current rootfs directory as Resolved.
Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

Still works in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:58 PM · VyOS 1.4 Sagitta
Apachez closed T5440: Restore pre/postconfig scripts if user deleted them as Resolved.
Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5437: logrotate.service fails to start.

Seems to still be happy in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:54 PM · VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.
Aug 14 2023, 9:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

Verified in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 9:50 PM · VyOS 1.4 Sagitta
Apachez created T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.
Aug 14 2023, 9:41 PM · VyOS 1.4 Sagitta
Apachez created T5478: Cannot configure resolver-cache options for firewall.
Aug 14 2023, 9:16 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

1:
Shouldnt set firewall global-options resolver-cache have "enable" and "disable" as options?

Aug 14 2023, 9:10 PM · VyOS 1.4 Sagitta
Apachez closed T5461: Improve rootfs directory variable as Resolved.
Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5461: Improve rootfs directory variable.

Looks like its working as expected in VyOS 1.4-rolling-202308140557:

Aug 14 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5473: Detect what conflicts with POSIX mode.

What is the purpose of:

Aug 14 2023, 11:08 AM · VyOS Rolling, Bugs

Aug 12 2023

Apachez created T5471: Conntrack logging doesnt seem to be working.
Aug 12 2023, 8:53 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.2), VyOS Rolling
Apachez added a comment to T4818: IPv6 NDP not working everytime.

How is your IPv6 config from the VyOS config?

Aug 12 2023, 5:08 PM · VyOS Rolling, Bugs
Apachez added a comment to T5090: Add support for disk encryption during installation.

A workaround in the meantime:

Aug 12 2023, 8:24 AM · VyOS 1.5 Circinus
Apachez added a comment to T5090: Add support for disk encryption during installation.

And in that case the attacker would just replace your router with their own since they already got physical access to the box.

Aug 12 2023, 6:40 AM · VyOS 1.5 Circinus
Apachez created T5468: Remove unused manpages to free up space.
Aug 12 2023, 6:32 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5090: Add support for disk encryption during installation.

The problem is how to make sure that the router can boot and reboot (for example "set system option reboot-on-panic" is handy) on itself without somebody having to connect to its console before it starts to function again. Really shitty situation for a remote site because then somebody needs to visit it aswell.

Aug 12 2023, 5:30 AM · VyOS 1.5 Circinus
Apachez added a comment to T4818: IPv6 NDP not working everytime.
  1. How is the physical topology (can you provide a drawing)?
Aug 12 2023, 5:17 AM · VyOS Rolling, Bugs

Aug 11 2023

Apachez added a comment to T5456: Add alias for "show ipv6 bgp".

Its not possible to "symlink" it?

Aug 11 2023, 7:26 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5456: Add alias for "show ipv6 bgp".

But at the same time it would help others who migrate to VyOS from Cisco, Arista etc.

Aug 11 2023, 3:17 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5461: Improve rootfs directory variable.

PR created: https://github.com/vyos/vyatta-op/pull/66

Aug 11 2023, 7:25 AM · VyOS 1.4 Sagitta
Apachez claimed T5461: Improve rootfs directory variable.
Aug 11 2023, 7:10 AM · VyOS 1.4 Sagitta
Apachez created T5461: Improve rootfs directory variable.
Aug 11 2023, 7:09 AM · VyOS 1.4 Sagitta

Aug 10 2023

Apachez added a comment to T5460: Firewall - remove config-trap.

Its good for traceability to get a snmp trap sent when the firewall config has been altered/changed/(re-)applied.

Aug 10 2023, 9:30 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5458: USB Console options is missing for a new image after "add system image" upgrade.

Yeah, no worries.

Aug 10 2023, 2:28 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

Im biased but here are my testresults using modified VyOS 1.4-rolling-202308060317:

Aug 10 2023, 2:20 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5458: USB Console options is missing for a new image after "add system image" upgrade.

According to https://www.kernel.org/doc/html/v6.1/admin-guide/serial-console.html

Aug 10 2023, 11:49 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T5458: USB Console options is missing for a new image after "add system image" upgrade.

There were no screenshots included with this task?

Aug 10 2023, 11:38 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

PR created: https://github.com/vyos/vyatta-op/pull/65

Aug 10 2023, 10:42 AM · VyOS 1.4 Sagitta
Apachez claimed T5457: Add environmental variable pointing to current rootfs directory.
Aug 10 2023, 10:16 AM · VyOS 1.4 Sagitta
Apachez created T5457: Add environmental variable pointing to current rootfs directory.
Aug 10 2023, 9:33 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5444: R8169 driver crash.

It seems to exist for current Debian 12.1 (bookworm) so I think it should be a relativily simple task to add that if not already existing:

Aug 10 2023, 7:56 AM
Apachez created T5456: Add alias for "show ipv6 bgp".
Aug 10 2023, 7:33 AM · VyOS 1.4 Sagitta
Apachez created T5455: Migrate SSH fingerprints to the new image on upgrade.
Aug 10 2023, 7:15 AM · VyOS 1.5 Circinus (2025.11)
Apachez created T5454: Add zebra dplane limit as a configurable option of FRR.
Aug 10 2023, 6:32 AM · VyOS Rolling
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Sounds almost related to this longrunning shitshow between FRR and the Linux kernel:

Aug 10 2023, 6:12 AM · VyOS Rolling, Bugs

Aug 7 2023

Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

I tried digging through google if somebody else have encountered the same but I couldnt find any obvious hints (except for the zebra nexthop-group keep 1 already mentioned).

Aug 7 2023, 4:51 PM · VyOS Rolling, Bugs
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

I added a comment to https://github.com/FRRouting/frr/issues/12239 so hopefully there might be some other commands or stuff to do other than the debug-commands to hunt this thing down.

Aug 7 2023, 3:40 PM · VyOS Rolling, Bugs
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

And the logs looks the same as in your original post?

Aug 7 2023, 3:18 PM · VyOS Rolling, Bugs
Apachez added a comment to T5444: R8169 driver crash.

Dont count on it - the way things works on internet is that there are alot of people complaining at stuff but very few who does something about it :-)

Aug 7 2023, 8:49 AM

Aug 6 2023

Apachez added a comment to T5444: R8169 driver crash.

If it crashes it should be reported upstream to kernel.org (and the maintainer for the r8169 driver) since VyOS is using the latest Linux Kernel LTS (current version 6.1.43 as of writing):

Aug 6 2023, 7:44 AM

Aug 5 2023

Apachez added a comment to T5417: nft -o (optimizing ruleset) fails with error: "internal:0:0-0: Error: Could not process rule: File exists" .

There is a bugzilla opened for this issue: https://bugzilla.netfilter.org/show_bug.cgi?id=1697

Aug 5 2023, 10:31 PM · VyOS Rolling, Bugs
Apachez added a comment to T5406: "update webproxy blacklists" fails when vrf is being configured.

I can confirm that updating blacklist now is vrf aware and functional:

Aug 5 2023, 10:23 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

PR created: https://github.com/vyos/vyos-1x/pull/2135

Aug 5 2023, 10:01 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5440: Restore pre/postconfig scripts if user deleted them.

PR created: https://github.com/vyos/vyos-1x/pull/2135

Aug 5 2023, 10:00 PM · VyOS 1.4 Sagitta
Apachez reopened T5436: vyos-preconfig-bootup.script is missing as "Open".
Aug 5 2023, 9:36 PM · VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.

Added task https://vyos.dev/T5440 to fix the issue of preconfig-script doesnt show up in /config/scripts after system upgrade (add system image).

Aug 5 2023, 9:35 PM · VyOS 1.4 Sagitta
Apachez claimed T5440: Restore pre/postconfig scripts if user deleted them.
Aug 5 2023, 9:33 PM · VyOS 1.4 Sagitta
Apachez created T5440: Restore pre/postconfig scripts if user deleted them.
Aug 5 2023, 9:33 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

I need some help with this one.

Aug 5 2023, 7:31 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5437: logrotate.service fails to start.

It seems happy for now:

Aug 5 2023, 7:02 PM · VyOS 1.4 Sagitta

Aug 4 2023

Apachez added a comment to T5439: Upgrade to FRR version 9.0 added new daemons which must be adjusted.

Note, if mgmtd is of no use in VyOS then the preferred is to have it disabled all together (after updating daemons.tmpl in case it gets enabled in future).

Aug 4 2023, 11:44 AM · VyOS 1.4 Sagitta
Apachez created T5439: Upgrade to FRR version 9.0 added new daemons which must be adjusted.
Aug 4 2023, 11:42 AM · VyOS 1.4 Sagitta
Apachez committed rVYOSONEX5a987d4a484b: T5436: Add missing preconfig-script.
Aug 4 2023, 11:02 AM
Apachez added a comment to T5436: vyos-preconfig-bootup.script is missing.

PR created: https://github.com/vyos/vyos-1x/pull/2132

Aug 4 2023, 10:42 AM · VyOS 1.4 Sagitta
Apachez claimed T5436: vyos-preconfig-bootup.script is missing.
Aug 4 2023, 10:15 AM · VyOS 1.4 Sagitta
Apachez created T5437: logrotate.service fails to start.
Aug 4 2023, 6:34 AM · VyOS 1.4 Sagitta
Apachez created T5436: vyos-preconfig-bootup.script is missing.
Aug 4 2023, 6:32 AM · VyOS 1.4 Sagitta

Aug 3 2023

Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Note also that 1.4 rolling as of today (3rd aug) uses FRR 9.0 (previously I think 8.5.4 were used or something like that).

Aug 3 2023, 11:15 AM · VyOS Rolling, Bugs
Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Note that you had an "s" too much in your command.

Aug 3 2023, 10:14 AM · VyOS Rolling, Bugs
Apachez added a comment to T5431: Services not enabled or configured are started anyway within frr-family.

Found that the defaults in daemons-file are set by VyOS in /usr/share/vyos/templates/frr/daemons.frr.tmpl

Aug 3 2023, 9:28 AM · VyOS 1.4 Sagitta
Apachez created T5433: Include memtest86+ as boot-option.
Aug 3 2023, 8:56 AM
Apachez created T5432: Add boot timeout option.
Aug 3 2023, 8:09 AM · VyOS Rolling
Apachez created T5431: Services not enabled or configured are started anyway within frr-family.
Aug 3 2023, 6:58 AM · VyOS 1.4 Sagitta

Aug 1 2023

Apachez created T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.
Aug 1 2023, 11:36 PM · VyOS Rolling, Bugs
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Done!

Aug 1 2023, 8:22 PM · VyOS 1.4 Sagitta
Apachez closed T5399: "show ntp" fails when vrf is being configured as Resolved.
Aug 1 2023, 8:22 PM · VyOS 1.4 Sagitta

Jul 30 2023

Apachez added a comment to T5414: dhcp-server does not allow valid bootfile-names.

Just to sync this task to PR 2118:

Jul 30 2023, 11:17 AM · VyOS 1.4 Sagitta
Apachez added a comment to T4502: Consider implementing (NAT/other) flow table offload.

As mentioned in https://vyos.dev/T5419 the offloading should not only apply for NAT.

Jul 30 2023, 8:06 AM · VyOS 1.4 Sagitta

Jul 29 2023

Apachez created T5419: Software/Hardware fastpath with nftables flowtable.
Jul 29 2023, 11:59 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5417: nft -o (optimizing ruleset) fails with error: "internal:0:0-0: Error: Could not process rule: File exists" .

This particular case was resolved by adding:

Jul 29 2023, 10:46 PM · VyOS Rolling, Bugs
Apachez created T5417: nft -o (optimizing ruleset) fails with error: "internal:0:0-0: Error: Could not process rule: File exists" .
Jul 29 2023, 9:44 PM · VyOS Rolling, Bugs
Apachez added a comment to T5414: dhcp-server does not allow valid bootfile-names.

I added this comment to PR 2118:

Jul 29 2023, 7:58 PM · VyOS 1.4 Sagitta
Apachez added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

A not too uncommon workaround for this is to disable the lease-file (if possible) and give out leases based on option82 information instead.

Jul 29 2023, 7:41 PM · VyOS 1.5 Circinus
Apachez added a comment to T5413: Deny the opportunity to use one public/private key pair on both wireguard peers..

Is this a limit of wireguard?

Jul 29 2023, 7:38 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Jul 27 2023

Apachez added a comment to T5404: Ability to completely disable firewall/conntrack.

Then how come conntrack modules are loaded (and there is content in the ruleset "sudo nft -s list ruleset") when I have no firewall rules configured?

Jul 27 2023, 9:25 AM · VyOS 1.4 Sagitta
Apachez created T5406: "update webproxy blacklists" fails when vrf is being configured.
Jul 27 2023, 2:43 AM · VyOS 1.4 Sagitta
Apachez created T5405: Add VRF support for "update geoip".
Jul 27 2023, 2:37 AM · VyOS Rolling
Apachez created T5404: Ability to completely disable firewall/conntrack.
Jul 27 2023, 2:24 AM · VyOS 1.4 Sagitta

Jul 26 2023

Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Tested and verified as described in the pull request:

Jul 26 2023, 5:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Oh, and the reason for why using chrony instead of ntpsec is?

Jul 26 2023, 5:52 PM
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Why this limit?

Jul 26 2023, 5:00 PM
Apachez committed rVYOSONEXb3eaa3c11a37: T5399: VRF-support for show ntp.
Jul 26 2023, 11:48 AM
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Pull request created: https://github.com/vyos/vyos-1x/pull/2112

Jul 26 2023, 9:51 AM · VyOS 1.4 Sagitta

Jul 25 2023

Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

I can confirm that altering line 21 as suggested fixes this issue.

Jul 25 2023, 11:29 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5116: Better VRF support.

Out of the blue it seems like "network namespaces" would solve alot of current VRF compatability issues within VyOS:

Jul 25 2023, 8:34 PM · VyOS Rolling
Apachez added a comment to T5371: "system name-server" is not vrf aware.

Workaround until "system name-server" becomes vrf aware seems to be to change context into vrf INTERNET and then do a ping with VRF syntax like so:

Jul 25 2023, 7:42 PM · VyOS Rolling, Bugs
Apachez added a comment to T5374: Ability to set 24-hour time format.

I would vote for:

Jul 25 2023, 7:40 PM · VyOS 1.4 Sagitta
Apachez created T5399: "show ntp" fails when vrf is being configured.
Jul 25 2023, 3:35 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Doing some more digging it turned out that VyOS doesnt support nested routing so the gateway must be reachable (at least IP-address wise) through a physical interface - I have updated the script in the original post to adjust for that (added variable GATEWAY).

Jul 25 2023, 1:04 PM · VyOS Rolling, Bugs
Apachez updated the task description for T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.
Jul 25 2023, 12:57 PM · VyOS Rolling, Bugs

Jul 24 2023

Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

But they shouldnt take several minutes and this alone can be a reason for why not putting VyOS into production.

Jul 24 2023, 4:58 PM · VyOS Rolling, Bugs

Jul 23 2023

Apachez updated the task description for T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.
Jul 23 2023, 3:16 AM · VyOS Rolling, Bugs